Privacy Policy
Last updated 19 June 2026
Enki Digital Pty Ltd ("Enki", "we", "us", "our") provides the Enki Bookkeep service (the "Service"). We respect your privacy and are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). We commit to handling personal information in accordance with the APPs whether or not the small-business exemption applies to us, because our customers and their advisers expect that standard and because we expect the law to require it.
This policy explains how we collect, hold, use, disclose, and protect personal information. It applies to our handling of personal information as an organisation. Where we process personal information contained in a customer's data on the customer's behalf, the customer is responsible for its own privacy obligations to the individuals concerned, and this policy operates alongside our Terms of Service.
1. The personal information we collect
Depending on how you interact with us, we may collect:
- Account and contact information — name, business name, email, phone, role, and login credentials.
- Billing information — billing contact, ABN, and payment details (card details are handled by our payment processor; we do not store full card numbers).
- Customer Data you upload — financial documents and records (such as bank statements, supplier invoices, rent receipts, and lease information). These may contain personal information about you and about third parties, including your personnel, tenants, suppliers, and individuals named in transaction narrations or invoices.
- Usage and technical data — log data, device and browser information, IP address, and interactions with the Service, collected to operate, secure, and improve it.
- Communications — correspondence with our support and the content of your enquiries.
We generally do not seek sensitive information (as defined in the Privacy Act). Please do not upload sensitive information unless it is necessary for the Service and you have the right to provide it.
2. How we collect personal information
We collect personal information: directly from you and your authorised users; from documents and data you or your agents upload; automatically through your use of the Service; from services you choose to connect (such as accounting software or, in future, bank-data feeds provided through accredited providers, with the necessary consents); and, where lawful, from third parties acting on your behalf.
3. Why we use personal information (purposes)
We use personal information to:
- provide, operate, maintain, and secure the Service, including ingesting documents and using automated and AI processing to extract data and suggest coding;
- perform reconciliation and generate records, summaries, and export files for your review;
- authenticate users and manage accounts, access, and multi-tenancy;
- provide support and respond to enquiries;
- bill and process payments;
- monitor, protect, and improve the security, integrity, and performance of the Service;
- comply with our legal obligations and enforce our terms; and
- improve and develop the Service, including by generating aggregated and de-identified insights that do not identify any individual.
We use personal information only for these purposes, for a directly related purpose you would reasonably expect, or as otherwise permitted or required by law or with your consent.
4. Automated and AI-assisted processing (transparency)
4.1 The Service uses automated processes and third-party AI models to read uploaded documents and to suggest transaction data and coding (including account and GST treatment). The kinds of personal information used in this processing include the contents of the documents you upload and the transaction information they contain.
4.2 These are suggestions, subject to human review. The Service does not finalise records, lodge anything, or make decisions that produce legal or similarly significant effects about an individual without a human reviewing and approving them. The outputs assist your bookkeeping; they are not automated decisions about individuals.
4.3 We maintain a record of which model and process produced each suggestion to support review and auditability. We provide this transparency consistent with our obligations under the APPs, including the automated-decision-making transparency requirements as they commence.
5. Disclosure and our sub-processors
5.1 We do not sell personal information. We disclose it only as described here.
5.2 Service providers (sub-processors). We use trusted providers to deliver the Service, who may handle personal information on our behalf under contractual obligations to protect it and use it only for our purposes. Current categories include:
- Cloud hosting, database, authentication, and storage — Supabase, with primary data hosting in Sydney, Australia;
- Application hosting and delivery — Vercel;
- AI model providers, accessed through a model gateway — Anthropic, OpenAI, Google, used to extract and suggest coding;
- Transactional email — Resend;
- Payment processing — Stripe;
- Error monitoring and analytics — Sentry and PostHog;
- (Future) accounting integrations and bank-data feeds — Xero or MYOB; an accredited CDR provider.
A current list is available on request at hello@enkidigital.solutions. We update this list as our providers change.
5.3 Other disclosures. We may disclose personal information: to your authorised users and the advisers you nominate (such as your accountant); where required or authorised by law, or to a regulator, court, or authority; to protect our rights, safety, or property, or those of others; and to a successor in connection with a business sale or restructure (subject to confidentiality).
6. Cross-border disclosure
6.1 We store the primary copy of Customer Data in Australia (Sydney). However, some of our sub-processors — in particular the AI model providers used to extract and suggest coding, and some application-delivery infrastructure — may process personal information outside Australia (including in the United States or other locations).
6.2 Before disclosing personal information to an overseas recipient, we take reasonable steps appropriate to the circumstances to protect it, including engaging providers under data-processing terms with appropriate safeguards, requiring that your content is not used to train the providers' AI models, and using zero-data-retention or equivalent protections where reasonably practicable.
6.3 By using the Service and uploading data, you acknowledge this overseas processing. Where the APPs require, this means we remain accountable for the handling of the personal information by those recipients.
7. Security
We hold personal information using technical and organisational measures designed to protect it from misuse, interference, loss, and unauthorised access, modification, or disclosure, as described in our Data Security Policy (including encryption in transit and at rest, database row-level access controls, multi-tenant isolation, least-privilege access, and audit logging). No system is completely secure; we cannot guarantee absolute security.
8. Retention and destruction
8.1 We keep personal information only for as long as needed for the purposes in this policy, to provide the Service, and to meet legal and record-keeping requirements.
8.2 Taxation records. Records relevant to taxation generally must be kept for at least five years under Australian law. You are responsible for retaining your own records (including exports from the Service) to meet those obligations.
8.3 When personal information is no longer needed and we are not required to retain it, we take reasonable steps to destroy it or de-identify it. On termination, our Terms of Service govern export and deletion of Customer Data; backups are deleted in the ordinary cycle.
9. Access, correction, and complaints
9.1 You may request access to, or correction of, personal information we hold about you by contacting our Privacy Officer at hello@enkidigital.solutions. We will respond within a reasonable time and as required by the APPs. We may need to verify your identity, and in limited circumstances permitted by law we may decline access, in which case we will explain why. There is no fee for making a request; we may charge a reasonable cost for providing access.
9.2 Much personal information in Customer Data can be accessed and corrected directly through the Service or via your account administrator.
9.3 Complaints. If you believe we have breached the APPs, contact our Privacy Officer at hello@enkidigital.solutions. We will acknowledge and investigate and aim to respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. Data breaches
We maintain a data-breach response plan. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will assess it and, where the Notifiable Data Breaches scheme requires, notify the affected individuals and the OAIC as soon as practicable.
11. Cookies and analytics
The Service uses cookies and similar technologies necessary to operate, secure, and improve it (for example, to keep you signed in and to understand usage). You can control cookies through your browser; disabling some may affect functionality.
12. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you.
14. Contact us
Privacy Officer, Enki Digital Pty Ltd — hello@enkidigital.solutions, Australia.
This policy describes how Enki handles personal information. It is not tax, financial, or legal advice. © 2026 Enki Digital Pty Ltd.